Vulnerabilities
Vulnerable Software
Ibm:  >> Api Connect  >> 2018.4.1.10  Security Vulnerabilities
IBM API Connect's API Manager 2018.4.1.0 through 2018.4.1.12 is vulnerable to privilege escalation. An invitee to an API Provider organization can escalate privileges by manipulating the invitation link. IBM X-Force ID: 185508.
CVSS Score
7.2
EPSS Score
0.005
Published
2020-09-03
IBM API Connect V2018.4.1.0 through 2018.4.1.11 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 181324.
CVSS Score
5.9
EPSS Score
0.001
Published
2020-06-29
IBM API Connect V2018.4.1.0 through 2018.4.1.10 could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim. IBM X-Force ID: 174859.
CVSS Score
5.4
EPSS Score
0.001
Published
2020-05-12
IBM API Connect's V2018.4.1.0 through 2018.4.1.10 management server has an unsecured api which can be exploited by an unauthenticated attacker to obtain sensitive information. IBM X-Force ID: 178322.
CVSS Score
5.3
EPSS Score
0.002
Published
2020-05-12


Contact Us

Shodan ® - All rights reserved